golang-github-containers-psgo: CVE-2022-1227

Related Vulnerabilities: CVE-2022-1227  

Debian Bug report logs - #1020907
golang-github-containers-psgo: CVE-2022-1227

version graph

Reported by: Vignesh Raman <vignesh.raman@collabora.com>

Date: Wed, 28 Sep 2022 10:33:01 UTC

Severity: important

Tags: bullseye, patch, security

Found in version golang-github-containers-psgo/1.5.2-1

Fixed in version golang-github-containers-psgo/1.7.1+ds1-1

Done: Salvatore Bonaccorso <carnil@debian.org>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, vignesh.raman@collabora.com, Debian Go Packaging Team <team+pkg-go@tracker.debian.org>:
Bug#1020907; Package src:golang-github-containers-psgo. (Wed, 28 Sep 2022 10:33:03 GMT) (full text, mbox, link).


Acknowledgement sent to Vignesh Raman <vignesh.raman@collabora.com>:
New Bug report received and forwarded. Copy sent to vignesh.raman@collabora.com, Debian Go Packaging Team <team+pkg-go@tracker.debian.org>. (Wed, 28 Sep 2022 10:33:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Vignesh Raman <vignesh.raman@collabora.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: golang-github-containers-psgo: CVE-2022-1227
Date: Wed, 28 Sep 2022 16:00:51 +0530
[Message part 1 (text/plain, inline)]
Source: golang-github-containers-psgo
Version: 1.5.2-1
Severity: important
Tags: patch
X-Debbugs-Cc: vignesh.raman@collabora.com

Dear Maintainer,

The following vulnerability for golang-github-containers-psgo is fixed in bookworm,
https://security-tracker.debian.org/tracker/CVE-2022-1227

We have backported the CVE fixes to bullseye since we are working on
debian bullseye derivative and want to send the patches to debian.
We understand these issues are not DSA and have to go though a point
release.

Please could you review the attached patch and apply in bullseye.
Have created a merge request also for review
https://salsa.debian.org/go-team/packages/golang-github-containers-psgo/-/merge_requests/2

Regards,
Vignesh

-- System Information:
Debian Release: 11.1
  APT prefers stable
  APT policy: (700, 'stable'), (650, 'testing'), (600, 'unstable'), (500, 'stable-updates'), (500, 'stable-security')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-9-amd64 (SMP w/8 CPU threads)
Kernel taint flags: TAINT_OOT_MODULE
Locale: LANG=en_IN, LC_CTYPE=en_IN (charmap=UTF-8), LANGUAGE=en_IN:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
[0001-internal-proc-do-not-join-the-process-user-namespace.patch (text/plain, attachment)]

Added tag(s) security. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 28 Sep 2022 11:45:02 GMT) (full text, mbox, link).


Marked as fixed in versions golang-github-containers-psgo/1.7.1+ds1-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 28 Sep 2022 11:48:03 GMT) (full text, mbox, link).


Marked Bug as done Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 28 Sep 2022 11:48:03 GMT) (full text, mbox, link).


Notification sent to Vignesh Raman <vignesh.raman@collabora.com>:
Bug acknowledged by developer. (Wed, 28 Sep 2022 11:48:04 GMT) (full text, mbox, link).


Message sent on to Vignesh Raman <vignesh.raman@collabora.com>:
Bug#1020907. (Wed, 28 Sep 2022 11:48:08 GMT) (full text, mbox, link).


Message #16 received at 1020907-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 1020906-submitter@bugs.debian.org, 1020907-submitter@bugs.debian.org
Subject: closing 1020907, closing 1020906
Date: Wed, 28 Sep 2022 13:44:53 +0200
# track some metadata on fixed version
close 1020907 1.7.1+ds1-1
close 1020906 3.4.6+ds1-1
thanks




Added tag(s) bullseye. Request was from Vignesh Raman <vignesh.raman@collabora.com> to control@bugs.debian.org. (Wed, 28 Sep 2022 13:15:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Sep 28 13:21:14 2022; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.